Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 301 801

Количество 301 801

github логотип

GHSA-28r8-9g34-2x25

больше 3 лет назад

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

EPSS: Низкий
github логотип

GHSA-28r8-6q2m-x9g4

больше 3 лет назад

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-28r7-8r62-w9hj

28 дней назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

EPSS: Низкий
github логотип

GHSA-28r6-jm5h-mrgg

больше 3 лет назад

Access control bypass in Beego

EPSS: Низкий
github логотип

GHSA-28r4-58h5-m5rr

больше 3 лет назад

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28r2-q6m8-9hpx

больше 3 лет назад

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-28qw-8jmg-32wx

почти 2 года назад

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qr-hqrv-mhvr

больше 3 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-28qq-773c-49rf

больше 3 лет назад

SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

EPSS: Низкий
github логотип

GHSA-28qp-wgp5-fp7m

больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

EPSS: Низкий
github логотип

GHSA-28qp-rcr7-xp4g

8 месяцев назад

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-28qp-98vv-5xqx

больше 3 лет назад

The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28qp-8c7m-wc33

больше 3 лет назад

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28qm-wmpf-4vwh

больше 3 лет назад

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

EPSS: Низкий
github логотип

GHSA-28qm-6v7q-2wqv

больше 3 лет назад

Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28qj-gvxv-p5g9

почти 2 года назад

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

CVSS3: 5
EPSS: Средний
github логотип

GHSA-28qj-9gmx-6vpj

больше 3 лет назад

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

EPSS: Низкий
github логотип

GHSA-28qj-36f6-4995

больше 3 лет назад

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-28qh-hp2x-hp83

больше 1 года назад

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-28qh-gf6m-p898

3 месяца назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28r8-9g34-2x25

A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28r8-6q2m-x9g4

The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28r7-8r62-w9hj

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki WebAuthn extension allows Stored XSS.This issue affects MediaWiki WebAuthn extension: 1.39, 1.43, 1.44.

0%
Низкий
28 дней назад
github логотип
GHSA-28r6-jm5h-mrgg

Access control bypass in Beego

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28r4-58h5-m5rr

In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28r2-q6m8-9hpx

HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion

CVSS3: 8.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28qw-8jmg-32wx

Transient DOS when processing a NULL buffer while parsing WLAN vdev.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-28qr-hqrv-mhvr

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-28qq-773c-49rf

SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28qp-wgp5-fp7m

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-28qp-rcr7-xp4g

IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-28qp-98vv-5xqx

The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qp-8c7m-wc33

Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qm-wmpf-4vwh

The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qm-6v7q-2wqv

Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.

CVSS3: 6.5
5%
Низкий
больше 3 лет назад
github логотип
GHSA-28qj-gvxv-p5g9

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

CVSS3: 5
31%
Средний
почти 2 года назад
github логотип
GHSA-28qj-9gmx-6vpj

Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-28qj-36f6-4995

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-28qh-hp2x-hp83

Deep Sea Electronics DSE855 Factory Reset Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-23173.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-28qh-gf6m-p898

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PublishPress Gutenberg Blocks allows PHP Local File Inclusion. This issue affects Gutenberg Blocks: from n/a through 3.3.1.

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу